A cluster of security advisories has been published for Langflow, an open-source AI workflow tool, indicating serious...
A cluster of security advisories has been published for Langflow, an open-source AI workflow tool, indicating serious vulnerabilities including remote code execution, missing authentication, and path traversal.
confidence score
Strong evidence: 3 independent source classes support this read.
signal brief
A cluster of security advisories has been published for Langflow, an open-source AI workflow tool, indicating serious vulnerabilities including remote code execution, missing authentication, and path traversal. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-0770 to its Known Exploited Vulnerabilities catalog on July 21, 2026, requiring federal agencies to apply mitigations by July 24 (see CISA KEV entry). The Open Source Vulnerabilities (OSV) database has published 12 distinct advisories for Langflow between June 29 and July 13, 2026 (see PYSEC-2026-1521, PYSEC-2026-1522, PYSEC-2026-1523, PYSEC-2026-1524, PYSEC-2026-1525, PYSEC-2026-2565, PYSEC-2026-2566, PYSEC-2026-2567, PYSEC-2026-2568, PYSEC-2026-2569, PYSEC-2026-376, PYSEC-2026-377, PYSEC-2026-378, PYSEC-2026-379). These include critical issues such as remote code execution via validate_code(), missing authentication on critical API endpoints, and path traversal in knowledge bases. A dev release (1.12.0.dev6) was published on PyPI on July 26 (see PyPI), but no official patch has been confirmed for all listed CVEs. The accumulation of vulnerabilities suggests systemic security weaknesses, likely eroding developer trust and enterprise adoption.
What the sources said:
- CISA: "Langflow contains an inclusion of functionality from untrusted control sphere vulnerability that allows remote attackers to execute arbitrary code." (source)
- OSV advisory PYSEC-2026-1524: "Langflow Missing Authentication on Critical API Endpoints." (source)
- OSV advisory PYSEC-2026-379: "Unauthenticated Remote Code Execution in Langflow via Public Flow Build Endpoint." (source)
source data used
“CVE: CVE-2026-0770 Vendor/project: Langflow Product: Langflow Known ransomware campaign use: Unknown Due date: 2026-07-24 CWE: CWE-829 Langflow contains an inclusion of functionality from untrusted control sphere vulnerability that allows remote attackers to execute arbitrary code on...”
“A Python package with a built-in web application”
“Aliases: CVE-2024-9277, GHSA-355v-2rjx-fpx7 Inefficient Regular Expression Complexity in langflow”
“Aliases: CVE-2025-68477, GHSA-5993-7p27-66g5 Langflow vulnerable to Server-Side Request Forgery”
“Aliases: CVE-2024-48061, GHSA-5p5r-57fx-pmfr Langflow vulnerable to remote code execution”
“Aliases: CVE-2026-21445, GHSA-c5cp-vx83-jhqx, PYSEC-2026-2571 Langflow Missing Authentication on Critical API Endpoints”
“Aliases: CVE-2026-0770, GHSA-g22f-v6f7-2hrh Langflow affected by Remote Code Execution via validate_code() exec()”
“Aliases: CVE-2026-6597, GHSA-5jjf-wcvf-923w Langflow has an Information Leak through Incomplete API Key Redaction”
“Aliases: CVE-2026-42867, GHSA-79ph-745m-6wxq Langflow: Path Traversal in Knowledge Bases API via Creation Endpoint”
“Aliases: CVE-2026-34046, GHSA-8c4j-f57c-35cf, PYSEC-2026-2570 Langflow: Authenticated Users Can Read, Modify, and Delete Any Flow via Missing Ownership Check”
“Aliases: CVE-2026-6598, GHSA-9jpj-cph8-w449 Langflow: Cleartext Storage of Authentication Settings in Project Creation Endpoint”
“Aliases: CVE-2026-6599, GHSA-v66p-f7x3-4794 Langflow vulnerable to injection”
“Aliases: CVE-2026-27966, GHSA-3645-fxcv-hqr4 Langflow has Remote Code Execution in CSV Agent”
“Aliases: CVE-2026-42048, GHSA-9whx-c884-c68q Langflow Knowledge Bases API is Vulnerable to Path Traversal”
“Aliases: CVE-2026-55447, GHSA-ccv6-r384-xp75 Langflow: BaseFileComponent-based nodes arbitrary file read with RCE exploit”
“Aliases: CVE-2026-33017, GHSA-vwmf-pq79-vjvx Unauthenticated Remote Code Execution in Langflow via Public Flow Build Endpoint”
Decision support, not stock advice. This signal is research with cited evidence — not a recommendation to buy, sell, or hold any security.